A newly formed platform team, composed of experienced developers, initially faced significant friction when implementing compliance roadmaps. Developers encountered new workflows, multiple AWS accounts, and unfamiliar concepts, leading to a decline in developer experience. Documentation was often lengthy, outdated, and difficult to navigate, resulting in frequent support requests and frustration.
The team shifted its strategy from forced workflows to an empathetic approach, focusing on simplifying governance and prioritizing what truly mattered. Davide de Paolis explained that success came from aligning around a shared purpose rather than dictating changes, recognizing that forced adoption rarely works effectively.
Compliance initiatives were rolled out incrementally, using a three-pronged strategy: prevention, detection, and communication. This method involved informing developers first, then softly enforcing changes, and only later moving to stricter enforcement. This approach proved reusable across various internal compliance efforts.
A concrete example of this strategy's success was the re-implementation of resource tagging. An earlier initiative had failed due to inconsistency and manual processes. The team simplified tagging by reducing required tags and standardizing them with AWS Tag Policies and Service Control Policies to prevent untagged resources. Concurrently, they used the AWS Security Hub Resource Tagging Standard to detect existing non-compliant resources, combining prevention, detection, and notification for better engagement.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A platform team improved compliance adoption by simplifying governance, prioritizing key issues, and rolling out changes incrementally, as detailed by Davide de Paolis. This approach addressed initial developer friction caused by new workflows and poor documentation, leading to successful adoption through prevention, detection, and communication.